DLL注入修改输入表模块源码,IAT注入,文本到字节,读取输入表,RtlMoveMemory_IMAGE_DOS_HEADER,RtlMoveMemory_IMAGE_NT_HEADERS_1,RtlMoveMemory_IMAGE_NT_HEADERS_2,RtlMoveMemory_IMAGE_IMPORT_DESCRIPTOR_1,
系统结构:
IAT注入,文本到字节,读取输入表,RtlMoveMemory_IMAGE_DOS_HEADER,RtlMoveMemory_IMAGE_NT_HEADERS_1,RtlMoveMemory_IMAGE_NT_HEADERS_2,RtlMoveMemory_IMAGE_IMPORT_DESCRIPTOR_1,RtlMoveMemory_IMAGE_IMPORT_DESCRIPTOR_2,RtlMoveMemory_IMAGE_SECTION_HEADER_1,RtlMoveMemory_IMAGE_SECTION_HEADER_2,RtlMoveMemory_字节集,lstrcpyn_字节集,
======IAT
| |
| |------ IAT注入
| |
| |------ 文本到字节
| |
| |------ 读取输入表
| |
| |
======程序集1
| |
| |------ _启动子程序
| |
| |
======调用的Dll
| |
| |---[dll]------ RtlMoveMemory_IMAGE_DOS_HEADER
| |
| |---[dll]------ RtlMoveMemory_IMAGE_NT_HEADERS_1
| |
| |---[dll]------ RtlMoveMemory_IMAGE_NT_HEADERS_2
| |
| |---[dll]------ RtlMoveMemory_IMAGE_IMPORT_DESCRIPTOR_1
| |
| |---[dll]------ RtlMoveMemory_IMAGE_IMPORT_DESCRIPTOR_2
| |
| |---[dll]------ RtlMoveMemory_IMAGE_SECTION_HEADER_1
| |
| |---[dll]------ RtlMoveMemory_IMAGE_SECTION_HEADER_2
| |
| |---[dll]------ RtlMoveMemory_字节集
| |
| |---[dll]------ lstrcpyn_字节集
.版本 2
.DLL命令 RtlMoveMemory_IMAGE_DOS_HEADER, , , "RtlMoveMemory"
.参数 Destination, IMAGE_DOS_HEADER
.参数 Source, 整数型
.参数 Length, 整数型
.DLL命令 RtlMoveMemory_IMAGE_NT_HEADERS_1, , , "RtlMoveMemory"
.参数 Destination, IMAGE_NT_HEADERS
.参数 Source, 整数型
.参数 Length, 整数型
.DLL命令 RtlMoveMemory_IMAGE_NT_HEADERS_2, , , "RtlMoveMemory"
.参数 Destination, 整数型
.参数 Source, IMAGE_NT_HEADERS
.参数 Length, 整数型
.DLL命令 RtlMoveMemory_IMAGE_IMPORT_DESCRIPTOR_1, , , "RtlMoveMemory"
.参数 Destination, IMAGE_IMPORT_DESCRIPTOR, 数组
.参数 Source, 整数型
.参数 Length, 整数型
.DLL命令 RtlMoveMemory_IMAGE_IMPORT_DESCRIPTOR_2, , , "RtlMoveMemory"
.参数 Destination, 字节集
.参数 Source, IMAGE_IMPORT_DESCRIPTOR, 数组
.参数 Length, 整数型
.DLL命令 RtlMoveMemory_IMAGE_SECTION_HEADER_1, , , "RtlMoveMemory"
.参数 Destination, 整数型
.参数 Source, IMAGE_SECTION_HEADER, 数组
.参数 Length, 整数型
.DLL命令 RtlMoveMemory_IMAGE_SECTION_HEADER_2, , , "RtlMoveMemory"
.参数 Destination, IMAGE_SECTION_HEADER, 数组
.参数 Source, 整数型
.参数 Length, 整数型
.DLL命令 RtlMoveMemory_字节集, , , "RtlMoveMemory"
.参数 Destination, 整数型
.参数 Source, 字节集
.参数 Length, 整数型
.DLL命令 lstrcpyn_字节集, 整数型, , "lstrcpynA"
.参数 lpString1, 字节集
.参数 lpString2, 字节集
.参数 iMaxLength, 整数型